CRITICAL 9.3 CVE-2026-70855 Published 18 Aug 2026

Oracle Siebel Self Service Vulnerability Enables Unauthorized Data Access

Worried this affects one of your servers?

A vulnerability has been found in the Siebel Apps - Self Service product of Oracle Siebel CRM, specifically in the Helpdesk/Training component. The flaw is an easily exploitable HTTP access vulnerability that allows an unauthenticated attacker with network access to compromise the application.

Successful exploitation requires human interaction from a person other than the attacker. The vulnerability can significantly impact additional products (scope change) and may result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all accessible Siebel Apps - Self Service data.

  • Affected versions: 17.0 through 26.6
  • Attack vector: network via HTTP
  • Authentication: none required
  • User interaction: required
  • CVSS 3.1 Base Score: 9.3 (Confidentiality and Integrity impacts)
  • CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N)

Reference: CVE-2026-70855 on NVD

← Back to Security News